Jump to content

Recommended Posts

Posted

I really could do with some help setting up Microsoft InTune for MDM. It seems like a very complex product that has excellent possibilities IF we can get it working correctly. Just a little bit of background. We currently have about 200 iPads which are managed by Cisco Meraki. We are looking to move away from Meraki because InTune is included in out Microsoft Licensing. We are looking to make InTune work in a similar way to how Meraki is working. Below is what we currently do with Meraki to provision and manage an iPad:

 

 

  • Plug the device into an iMac and erase/prepare the iPad using Apple Configurator 2. The device then turns on and shows that it has been prepared for our College etc. The Meraki app downloads itself automatically and the device then shows in the Meraki management console for us to assign policies and apps.
  • We have a certain amount of apps that push automatically such as OWA, Office products and some additional apps. These apps install automatically to the iPad based on the settings and profiles setup in Meraki.
  • Staff are then able to sign into the App store to install their own additional apps if they wish.
  • We use policies in Meraki to lock the iPads down a little, for example a set desktop background, prevent the use of some apps, prevent changing the name or resetting the device etc.

 

All devices that will go into InTune are College owned, not user owned, we will not be allowing users to add their own individual devices. So we essentially want to provision an iPad, allow the device to be locked down, push apps automatically and then allow them to sign into their personal Apple account if they wish to download and install their own apps.

 

The thing I have noticed is that Meraki appears to be very much device based licensing, we don't really lock an iPad down to a specific user, although we can do this if we have to. With InTune it looks like the licensing is user based, so it would need to be locked down to a user I guess?

 

I hope this make sense for how we want InTune to work, any advice or help is much appreciated.

 

I have had a chat with a Microsoft representative about this, but they have not been helpful, they appear to have no idea how to set the product up in the way that we want it.

Posted

We moved from (Free) Meraki to Intune a while back. It's a slightly different way of thinking about things, but once you understand how it works, it's not too bad. And most of the pages have links to documentation guides.

 

First, you'll need to set up VPP and your apple push certificates, which should be similar to Meraki.

 

Then set up configurator enrollment (ultimately this should work in a similar way to Meraki)

https://docs.microsoft.com/en-us/intune/apple-configurator-enroll-ios#create-an-apple-configurator-profile-for-devices

We always use user based enrollment with an enrollment manager account for shared devices

https://docs.microsoft.com/en-us/intune/device-enrollment-manager-enroll

 

Apps and device configuration polices are pretty self explanatory. We've got it all based on user groups.

Required apps will automatically install, and available can be pulled down from the intune app. You'll need to make sure the users have intune licences assigned.

Posted
First question...I presume you have Azure AD to integrate with InTune?

 

Indeed we do have Azure AD Connect, all users are already in Azure, we use single sign on services and a bunch of other stuff with Azure so that part is already good to go hopefully.

 

We moved from (Free) Meraki to Intune a while back. It's a slightly different way of thinking about things, but once you understand how it works, it's not too bad. And most of the pages have links to documentation guides.

 

First, you'll need to set up VPP and your apple push certificates, which should be similar to Meraki.

 

Then set up configurator enrollment (ultimately this should work in a similar way to Meraki)

https://docs.microsoft.com/en-us/intune/apple-configurator-enroll-ios#create-an-apple-configurator-profile-for-devices

We always use user based enrollment with an enrollment manager account for shared devices

https://docs.microsoft.com/en-us/intune/device-enrollment-manager-enroll

 

Apps and device configuration polices are pretty self explanatory. We've got it all based on user groups.

Required apps will automatically install, and available can be pulled down from the intune app. You'll need to make sure the users have intune licences assigned.

 

I have tried a few things, we already have the MDM Push Cert setup, but beyond that I have just been playing around I guess would be the best way to describe it. I setup an Apple Configurator profile, exported it and added it to Apple Configurator, I even managed to get the device provisioned and it appeared in InTune, I could lock it and manage a few basic things, but beyond this, I couldn't assign profiles, I couldn't figure out how to push apps etc. In the end I just gave up. I was asking Microsoft about if we should be using user affinity etc, they seem to think that we would need to install the InTune app to manage the device, but we don't really want to have the user login to manage the device. The devices are college owned so we want to be able to manage it without a user logging in....

 

Microsoft didn't seem to give me any straight answers despite several 1 hour conference sessions with them, they kept just telling me about how great the product is, but none of that actually helped us with our requirements for our environment.

 

When you provision an iPad using configurator on Meraki it installs the Meraki app automatically, this app seems to help manage the apps and settings, but the user does not need to login to it. Do I need to have an app with InTune, can I get that app to install on provision ?

 

Sorry for all the questions here. It just surprises me that Microsoft actually came to us originally suggesting that we use InTune, and now that we are trying to pursue it, they seem to have no idea...

Posted
I'd dump configursator altogether and use DEP, I really don't understand why people cling onto this...

 

https://www.robinhobo.com/how-to-configure-apple-dep-within-microsoft-intune-and-migrate-existing-dep-devices-from-another-mdm-solution-to-microsoft-intune/

 

Isn't DEP for newly ordered iPads though? We have 200+ existing managed iPads at the moment, so the idea is to get them all back once Intune is working, wipe and prep them with Configurator and then give them back out.

Posted
Isn't DEP for newly ordered iPads though? We have 200+ existing managed iPads at the moment, so the idea is to get them all back once Intune is working, wipe and prep them with Configurator and then give them back out.

Depending on how long you've had them (and if the company you got them from is still around #misco#) then you might be able to add old orders into DEP. We got 2-3 year old kit provisioned on DEP.

 

I was asking Microsoft about if we should be using user affinity etc, they seem to think that we would need to install the InTune app to manage the device, but we don't really want to have the user login to manage the device. The devices are college owned so we want to be able to manage it without a user logging in....

Far as I'm aware, you don't need the intune app installed (but you'd need it for availible apps).

While you can manage device without assigned users, we found that user affinity makes it far easier. If you don't want your user to sign in or the device moves between users then you can use an enrollment manager account. But if the devices are one-to-one or assigned to a specific user then using user affinity with the assigned users 365 accounts does seem to be the best way to go.

Posted
Depending on how long you've had them (and if the company you got them from is still around #misco#) then you might be able to add old orders into DEP. We got 2-3 year old kit provisioned on DEP.

 

 

Far as I'm aware, you don't need the intune app installed (but you'd need it for availible apps).

While you can manage device without assigned users, we found that user affinity makes it far easier. If you don't want your user to sign in or the device moves between users then you can use an enrollment manager account. But if the devices are one-to-one or assigned to a specific user then using user affinity with the assigned users 365 accounts does seem to be the best way to go.

You can add devices as far back as 2011 into DEP, using the easy route to just pass over your Customer ID and get the Reseller ID into ASM and reset each iPad. Any other device can also be added to DEP via Apple Configurator without knowing at all where the iPad was bought from or whether the reseller does not exist anymore. The iPad must support iOS11 for this to work.

  • Thanks 1
Posted

Some of our iPads were purchased from places that do not appear to be part of DEP and do not have a Reseller ID. I remember looking at this in the past and we did hit a bit of a snag.

 

Moving forward we will probably start using DEP, but for now we still need to figure out how to best provision the iPads that we have with InTune.

 

I will give the articles a try and let you know :)

Posted

Okay so I have provisioned an iPad using Configurator at the moment after erasing and preparing it. It starts up and tells me that it has been configured for the organisation, I ran through the initial setup, connected to WiFi etc and the iPad appears in Apple Configurator - Devices inside of inTune and the Last contacted date is recent, so it seems that intune can see the device which is good.

 

The profile I used had User Affinity enabled. When the iPad first went to the home screen it came up the following:

 

"App Installation: Sign in to iTunes to allow "i.manage.microsoft.com" to manage and install apps.".

 

I signed into one of our generic accounts which resulted in the automatic installation of "Comp Portal". I assume I need to sign into this to continue digging into this. When I enter my email address on the sign in screen it should redirect to ADFS, but when redirecting it just comes up with:

 

"Company Portal Temporarily Unavailable. - The company portal app encountered a problem. If the problem persists, please contact your system administrator."

 

I do not appear to be able to get past this stage, am I missing something here? Our ADFS is working, we use ADFS all day long for a bunch of stuff which I have tested and it still works fine.

 

Is there something I am missing here? Also, is it possible to get the Comp Portal app to install without having to sign into itunes ?

 

Thanks very much :)

Posted
You will want to install the company portal app with VPP. To do this make sure you have a VPP account set up, the company portal app purchased in VPP and the token set up with intune. You will go to device enrollment>enrollment program tokens>select your profile> open the properties. Under Authenticate with Company Portal instead of Apple Setup Assistant you can Install Company Portal with VPP.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...